Skip to content

Save auth login profiles with the account's primary (SPOG) URL - #6854

Open
Peter-Feng-32 wants to merge 2 commits into
mainfrom
spog-login-poll
Open

Peter-Feng-32 wants to merge 2 commits into
mainfrom
spog-login-poll

Conversation

@Peter-Feng-32

@Peter-Feng-32 Peter-Feng-32 commented Sep 28, 2026 •

Copy link
Copy Markdown

Summary

databricks auth login saves the account's primary (SPOG) URL in the login.databricks.com flow. SPOG profiles keep the account-level token they get today.

  • Picking an account: look up GET /api/2.0/accounts/{account_id}/provisioned-urls/primary and save the profile with that URL.
  • Picking a workspace: if the workspace's /.well-known/databricks-config?include_primary_url=true returns a unified primary_url, run a second, account-level login through it and save a SPOG profile (account_id + workspace_id). If that login fails or is cancelled, the workspace profile is saved as before. The browser only asks to sign in again when there's no session on the SPOG host.
  • --resource on a SPOG host: resource indicators are only honored on workspace-level authorize, so with a workspace (?o=<id> or --workspace-id) the login runs at the workspace's own host, read from the SPOG host's ?o= OAuth metadata. Without a workspace, or if that host can't be found, login fails before opening the browser instead of silently ignoring the resource.

A host passed with --host is otherwise used as given. Lookups are best-effort; the workspace primary_url is only returned when the server flag databricks.login.enableDatabricksConfigDiscoveryPrimaryUrl is enabled.

Testing

Unit tests for the lookups (including 404 as "no primary URL"), the account and workspace picks (second login, its options, and the fallbacks), the primary-URL switch, and --resource routing. go test ./cmd/auth/... ./cmd/root/... ./libs/auth/... ./libs/databrickscfg/... and the auth acceptance tests pass. On staging, a SPOG --resource login was routed to the workspace's own host.

This pull request and its description were written by Isaac.

@eng-dev-ecosystem-bot

eng-dev-ecosystem-bot commented Sep 28, 2026 •

Copy link
Copy Markdown
Collaborator

Integration test report

Commit: 3dea8ed

Run: 37873866232

Env 🔄​flaky ✅​pass 🙈​skip Time
✅​ aws linux-2core-8gb 276 16 5:25
🔄​ aws-windows-latest-4core-16gb 2 276 14 4:19
✅​ azure linux-2core-8gb 275 16 5:08
✅​ azure-windows-latest-4core-16gb 277 14 3:38
✅​ gcp linux-2core-8gb 276 16 5:14
✅​ gcp-windows-latest-4core-16gb 278 14 3:45
Test Name aws-windows-latest-4core-16gb
🔄​ TestSyncNestedFolderSync 🔄​f
🔄​ TestExportDir 🔄​f
Top 6 slowest tests (at least 2 minutes):
duration env testname
3:57 gcp linux-2core-8gb TestAccept
3:52 aws linux-2core-8gb TestAccept
3:49 azure linux-2core-8gb TestAccept
3:42 gcp-windows-latest-4core-16gb TestAccept
3:38 aws-windows-latest-4core-16gb TestAccept
3:35 azure-windows-latest-4core-16gb TestAccept

@Peter-Feng-32 Peter-Feng-32 changed the title Look up account primary provisioned (SPOG) URL during auth login Save auth login profiles with the account's primary (SPOG) URL Oct 7, 2026
`auth login --host <spog>` with a workspace (`?o=<id>` or `--workspace-id`)
now gets a workspace-scoped token: the profile saves
discovery_url=<spog>/oidc/.well-known/oauth-authorization-server?o=<id>, so
login and refresh use the workspace's own OIDC while API calls go to the SPOG
host. This also makes `--resource` work on SPOG hosts. Without a workspace the
login stays account-level, and a host passed with --host is saved as given.

In the login.databricks.com flow, picking an account saves the account's
primary URL (/api/2.0/accounts/{id}/provisioned-urls/primary), and picking a
workspace saves a workspace-scoped SPOG profile when the workspace's
/.well-known/databricks-config?include_primary_url=true returns a unified
primary URL that serves its OAuth.

auth token, logout, auth profiles and re-login hints handle the new profile
type; host-only token requests without a workspace ID stay account-level.

Co-authored-by: Isaac <no-reply@databricks.com>
…e host

Drop the workspace-scoped SPOG profile type: SPOG profiles keep the
account-level token they get today, which older CLIs, SDKs that only pass
--host, and account APIs all work with.

- login.databricks.com: picking a workspace whose account has a primary
  (SPOG) URL runs a second, account-level login through it. If that login
  fails or is cancelled, the workspace profile is saved as before.
- --resource on a SPOG host with a workspace (?o= or --workspace-id) logs
  in at the workspace's own host, read from the SPOG host's ?o= OAuth
  metadata, because resource indicators are only honored on workspace-level
  authorize. Without a workspace, or if the host can't be found, login
  fails before opening the browser.

Co-authored-by: Isaac <no-reply@databricks.com>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants